[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Feb 12 20:10:30 GMT 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
08bb611d by security tracker role at 2022-02-12T20:10:22+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,11 @@
+CVE-2022-0574
+	RESERVED
+CVE-2022-0573
+	RESERVED
+CVE-2022-0572
+	RESERVED
+CVE-2022-0571
+	RESERVED
 CVE-2022-0570
 	RESERVED
 CVE-2022-0569
@@ -39,8 +47,8 @@ CVE-2022-0567
 	RESERVED
 CVE-2022-0566
 	RESERVED
-CVE-2022-0565
-	RESERVED
+CVE-2022-0565 (Exposure of Sensitive Information to an Unauthorized Actor in Packagis ...)
+	TODO: check
 CVE-2021-22590
 	RESERVED
 CVE-2020-22592
@@ -2907,7 +2915,7 @@ CVE-2022-23992
 CVE-2022-23991
 	RESERVED
 CVE-2022-23990 (Expat (aka libexpat) before 2.4.4 has an integer overflow in the doPro ...)
-	{DLA-2904-1}
+	{DSA-5073-1 DLA-2904-1}
 	- expat 2.4.3-3
 	NOTE: https://github.com/libexpat/libexpat/pull/551
 	NOTE: Introduced with: https://github.com/libexpat/libexpat/commit/cb8a4c756d057b948c1b41e7185dd69ef3ade3fb (R_1_95_4)
@@ -3651,7 +3659,7 @@ CVE-2022-23853 (The LSP (Language Server Protocol) plugin in KDE Kate before 21.
 	NOTE: Fixed by: https://commits.kde.org/kate/c5d66f3b70ae4778d6162564309aee95f643e7c9
 	NOTE: Fixed by: https://commits.kde.org/kate/7e08a58fb50d28ba96aedd5f5cd79a9479b4a0ad
 CVE-2022-23852 (Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML ...)
-	{DLA-2904-1}
+	{DSA-5073-1 DLA-2904-1}
 	- expat 2.4.3-2
 	NOTE: https://github.com/libexpat/libexpat/pull/550
 	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/847a645152f5ebc10ac63b74b604d0c1a79fae40 (R_2_4_4)
@@ -7086,32 +7094,32 @@ CVE-2022-0156 (vim is vulnerable to Use After Free ...)
 	NOTE: https://huntr.dev/bounties/47dded34-3767-4725-8c7c-9dcb68c70b36
 	NOTE: https://github.com/vim/vim/commit/9f1a39a5d1cd7989ada2d1cb32f97d84360e050f (v8.2.4040)
 CVE-2022-22827 (storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an in ...)
-	{DLA-2904-1}
+	{DSA-5073-1 DLA-2904-1}
 	- expat 2.4.3-1 (bug #1003474)
 	NOTE: https://github.com/libexpat/libexpat/pull/539
 	NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e (R_2_4_3)
 CVE-2022-22826 (nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 ha ...)
-	{DLA-2904-1}
+	{DSA-5073-1 DLA-2904-1}
 	- expat 2.4.3-1 (bug #1003474)
 	NOTE: https://github.com/libexpat/libexpat/pull/539
 	NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e (R_2_4_3)
 CVE-2022-22825 (lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integ ...)
-	{DLA-2904-1}
+	{DSA-5073-1 DLA-2904-1}
 	- expat 2.4.3-1 (bug #1003474)
 	NOTE: https://github.com/libexpat/libexpat/pull/539
 	NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e (R_2_4_3)
 CVE-2022-22824 (defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has ...)
-	{DLA-2904-1}
+	{DSA-5073-1 DLA-2904-1}
 	- expat 2.4.3-1 (bug #1003474)
 	NOTE: https://github.com/libexpat/libexpat/pull/539
 	NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e (R_2_4_3)
 CVE-2022-22823 (build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an  ...)
-	{DLA-2904-1}
+	{DSA-5073-1 DLA-2904-1}
 	- expat 2.4.3-1 (bug #1003474)
 	NOTE: https://github.com/libexpat/libexpat/pull/539
 	NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e (R_2_4_3)
 CVE-2022-22822 (addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an i ...)
-	{DLA-2904-1}
+	{DSA-5073-1 DLA-2904-1}
 	- expat 2.4.3-1 (bug #1003474)
 	NOTE: https://github.com/libexpat/libexpat/pull/539
 	NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e (R_2_4_3)
@@ -7693,7 +7701,7 @@ CVE-2022-0130 (Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a
 CVE-2021-46145 (The keyfob subsystem in Honda Civic 2012 vehicles allows a replay atta ...)
 	NOT-FOR-US: keyfob subsystem in Honda Civic 2012 vehicles
 CVE-2021-46143 (In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an int ...)
-	{DLA-2904-1}
+	{DSA-5073-1 DLA-2904-1}
 	- expat 2.4.3-1
 	NOTE: https://github.com/libexpat/libexpat/issues/532
 	NOTE: https://github.com/libexpat/libexpat/pull/538
@@ -9130,7 +9138,7 @@ CVE-2022-0080 (mruby is vulnerable to Heap-based Buffer Overflow ...)
 	NOTE: https://huntr.dev/bounties/59a70392-4864-4ce3-8e35-6ac2111d1e2e/
 	NOTE: https://github.com/mruby/mruby/commit/28ccc664e5dcd3f9d55173e9afde77c4705a9ab6
 CVE-2021-45960 (In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) pla ...)
-	{DLA-2904-1}
+	{DSA-5073-1 DLA-2904-1}
 	- expat 2.4.3-1 (bug #1002994)
 	NOTE: https://github.com/libexpat/libexpat/issues/531
 	NOTE: https://github.com/libexpat/libexpat/pull/534
@@ -9391,6 +9399,7 @@ CVE-2021-4190 (Large loop in the Kafka dissector in Wireshark 3.6.0 allows denia
 	NOTE: https://gitlab.com/wireshark/wireshark/-/issues/17811
 CVE-2021-4189 [ftplib should not use the host from the PASV response]
 	RESERVED
+	{DLA-2919-1}
 	- python3.10 <not-affected> (Fixed before initial upload to Debian unstable)
 	- python3.9 3.9.7-1
 	[bullseye] - python3.9 <no-dsa> (Minor issue)
@@ -66158,7 +66167,7 @@ CVE-2021-3178 (** DISPUTED ** fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10
 	NOTE: https://patchwork.kernel.org/project/linux-nfs/patch/20210111210129.GA11652@fieldses.org/
 	NOTE: Disputed/mild security relevance/impact
 CVE-2021-3177 (Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctyp ...)
-	{DLA-2619-1}
+	{DLA-2919-1 DLA-2619-1}
 	- python3.9 3.9.1-3
 	- python3.8 <removed>
 	- python3.7 <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/08bb611d5a996ae91766ba7452fe36684d6786b0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/08bb611d5a996ae91766ba7452fe36684d6786b0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220212/4b39d81b/attachment.htm>


More information about the debian-security-tracker-commits mailing list